Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-31459

Опубликовано: 14 мая 2024
Источник: nvd
CVSS3: 8
CVSS3: 7.2
EPSS Низкий

Описание

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the lib/plugin.php file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the api_plugin_hook() function in the lib/plugin.php file, which reads the plugin_hooks and plugin_config tables in database. The read data is directly used to concatenate the file path which is used for file inclusion. Version 1.2.27 contains a patch for the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*
Версия до 1.2.27 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02183
Низкий

8 High

CVSS3

7.2 High

CVSS3

Дефекты

CWE-98
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8
ubuntu
больше 1 года назад

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in the `lib/plugin.php` file, which reads the plugin_hooks and plugin_config tables in database. The read data is directly used to concatenate the file path which is used for file inclusion. Version 1.2.27 contains a patch for the issue.

CVSS3: 8
debian
больше 1 года назад

Cacti provides an operational monitoring and fault management framewor ...

CVSS3: 8
fstec
больше 1 года назад

Уязвимость функции api_plugin_hook() программного средства мониторинга сети Cacti, позволяющая нарушителю выполнить произвольный код

suse-cvrf
больше 1 года назад

Security update for cacti, cacti-spine

suse-cvrf
больше 1 года назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 84%
0.02183
Низкий

8 High

CVSS3

7.2 High

CVSS3

Дефекты

CWE-98
NVD-CWE-Other